testing-websocket-api-security - Test WebSocket APIs for security vulnerabilities
Tests WebSocket APIs for authentication, authorization, CSWSH, injection, input validation, denial-of-service, and information leakage issues.
Tags
Updated: 2026-10-05Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Discover WebSocket endpoints
- Analyze upgrade handshakes
- Test authentication enforcement
- Test authorization enforcement
- Test Origin validation
- Test message injection
- Test input validation
- Test message flooding
- Test oversized frames
- Assess information leakage
Inputs
- Authorized WebSocket endpoint
- Testing scope
- Authentication token
- WebSocket subprotocol
- WebSocket messages
- Injection payloads
Outputs
- Connection test results
- Authentication findings
- Authorization findings
- CSWSH findings
- Injection findings
- Input validation findings
- Denial-of-service findings
- Information leakage findings
- WebSocket frame observations
Requirements
- Written testing authorization
- Burp Suite Professional
- Python 3.10 or later
- websockets library
- asyncio library
- Browser developer tools
- wscat CLI tool
- WebSocket subprotocol knowledge
